Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2023-Feb-22 10:41:20 |
Detected languages |
English - United States
|
Debug artifacts |
D:\a\1\s\exe\Win32\Release\Procmon.pdb
|
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Process Monitor |
FileVersion | 3.93 |
InternalName | Process Monitor |
LegalCopyright | Copyright © 1996-2023 Mark Russinovich |
OriginalFilename | Process Monitor |
ProductName | Sysinternals Procmon |
ProductVersion | 3.93 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig2(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE is possibly a dropper. |
Resource RCDRIVERNT detected as a PE Executable.
Resource 1308 detected as a PE Executable. Resources amount for 76.2512% of the executable. |
Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2011 |
Suspicious | VirusTotal score: 1/71 (Scanned on 2023-07-09 03:35:42) | Antiy-AVL: RiskWare/Win64.Mimikatz |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x120 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2023-Feb-22 10:41:20 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xd4c00 |
SizeOfInitializedData | 0x423c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000A1D40 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xd6000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x4fe000 |
SizeOfHeaders | 0x400 |
Checksum | 0x502e05 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WS2_32.dll |
getsockname
listen recv send closesocket gethostbyname WSAGetLastError ntohs WSAStartup htonl inet_addr inet_ntoa bind connect accept htons socket gethostbyaddr WSASetLastError getservbyname getservbyport |
---|---|
VERSION.dll |
GetFileVersionInfoSizeW
VerQueryValueW GetFileVersionInfoW |
COMCTL32.dll |
ImageList_SetBkColor
ImageList_AddMasked ImageList_BeginDrag ImageList_EndDrag ImageList_DragEnter ImageList_DragLeave ImageList_DragMove ImageList_DragShowNolock ImageList_GetImageCount ImageList_DrawIndirect CreateStatusWindowW ImageList_SetOverlayImage InitCommonControlsEx ImageList_Add ImageList_Draw ImageList_GetIcon ImageList_ReplaceIcon ImageList_Create ImageList_GetIconSize ImageList_DrawEx ImageList_Destroy |
FLTLIB.DLL |
FilterSendMessage
FilterGetMessage FilterReplyMessage FilterConnectCommunicationPort |
KERNEL32.dll |
GetCurrentProcess
GetCurrentThreadId SuspendThread GetThreadContext SetThreadContext FlushInstructionCache VirtualAlloc VirtualProtect VirtualFree VirtualQuery GetFileSize SetFilePointer CreateFileMappingW UnmapViewOfFile LoadLibraryExA GetFullPathNameW GlobalMemoryStatusEx FreeResource Sleep CreateThread GetSystemTimeAsFileTime GetTickCount GetTickCount64 InitializeCriticalSection DeleteCriticalSection ExpandEnvironmentStringsW GetCurrentDirectoryW SetFileAttributesW GetSystemDirectoryW ReleaseSRWLockExclusive ReleaseSRWLockShared AcquireSRWLockExclusive AcquireSRWLockShared InitializeSRWLock GetSystemInfo RaiseException InitializeCriticalSectionEx GlobalAddAtomW EnumResourceNamesW CompareStringW GetLocaleInfoW lstrcmpW lstrcmpiW MultiByteToWideChar SetEndOfFile TryEnterCriticalSection MapViewOfFile FileTimeToLocalFileTime LocalFileTimeToFileTime ReadFile FormatMessageW FileTimeToSystemTime SystemTimeToFileTime GetDateFormatW GetTimeFormatW GetNumberFormatW QueryPerformanceCounter QueryPerformanceFrequency HeapCreate SetEvent ResetEvent ReleaseSemaphore CreateEventW WaitForMultipleObjects CreateSemaphoreW SetThreadPriority GetComputerNameA GetFileAttributesExW DecodePointer GetCurrentProcessId SetProcessShutdownParameters GetComputerNameW SetConsoleCtrlHandler OpenThread GetSystemDirectoryA TrySubmitThreadpoolCallback LoadLibraryA FindClose FindFirstFileW FindNextFileW SetEnvironmentVariableW ExpandEnvironmentStringsA GetStartupInfoW IsDebuggerPresent IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter WaitForSingleObjectEx InitializeCriticalSectionAndSpinCount OutputDebugStringW EncodePointer InterlockedPopEntrySList InterlockedPushEntrySList WideCharToMultiByte GetStringTypeW LCMapStringEx OpenProcess CreateProcessW TerminateProcess ExitProcess WaitForSingleObject GetLastError GetEnvironmentVariableW VerifyVersionInfoW lstrlenW MulDiv LoadLibraryW FreeLibrary GetCPInfo RtlUnwind TlsAlloc TlsGetValue TlsSetValue TlsFree GetModuleHandleExW GetConsoleCP ExitThread FreeLibraryAndExitThread CreateRemoteThreadEx GetThreadId ResumeThread GetCurrentThread LeaveCriticalSection EnterCriticalSection CloseHandle GetTempPathW WriteFile GetTempFileNameW DeleteFileW CreateFileW VerSetConditionMask GetModuleFileNameW GetPrivateProfileStringW GetPrivateProfileIntW FindResourceW SizeofResource LockResource LoadResource FindResourceExW GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc HeapDestroy GetFileAttributesW GlobalLock GlobalUnlock GlobalAlloc LocalFree LocalAlloc GetProcAddress GetModuleHandleW GetFileType GetCommandLineW GetStdHandle LoadLibraryExW GetVersionExW SetLastError IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetConsoleMode SetConsoleMode ReadConsoleInputW ReadConsoleW GetConsoleOutputCP GetFileSizeEx SetFilePointerEx FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW SetStdHandle FlushFileBuffers WriteConsoleW SetCurrentDirectoryW InitializeSListHead LCMapStringW |
USER32.dll |
GetKeyState
GetUpdateRect GetUpdateRgn ScrollWindowEx IntersectRect GetClassLongW EqualRect FlashWindowEx LoadStringA DrawEdge GetMessageW TranslateMessage DispatchMessageW PeekMessageW GetMessagePos PostQuitMessage GetWindowPlacement SetWindowPlacement CheckRadioButton CharLowerW LoadAcceleratorsW CreatePopupMenu RemoveMenu InsertMenuItemW SetRectEmpty ChildWindowFromPoint FindWindowExW FindWindowW SetForegroundWindow IsIconic WaitForInputIdle CreateIconFromResourceEx GetDlgItemInt GetActiveWindow RegisterWindowMessageW GetAsyncKeyState SetWindowTextA EnumChildWindows UnionRect GetPropW SetPropW DrawFrameControl CheckMenuRadioItem SetRect WindowFromPoint ClientToScreen AdjustWindowRectEx SetMenuDefaultItem GetMenuItemInfoW DeleteMenu AppendMenuW GetMenuItemCount GetMenuItemID GetSubMenu EnableMenuItem DestroyMenu LoadMenuW GetCapture SetFocus GetDlgCtrlID SetDlgItemInt CreateDialogParamW EndDeferWindowPos DeferWindowPos BeginDeferWindowPos GetClassInfoExW RegisterClassExW UnregisterClassW UnregisterHotKey RegisterHotKey TrackMouseEvent MonitorFromPoint IsDialogMessageW LoadIconW MapWindowPoints GetCursor GetCursorPos GetFocus LoadStringW MessageBeep SetActiveWindow GetDesktopWindow DialogBoxParamW LoadImageW GetWindow MessageBoxW EnableWindow IsDlgButtonChecked CheckDlgButton GetDlgItemTextW DestroyWindow IsWindow GetWindowRect SetDlgItemTextW GetAncestor GetMonitorInfoW MonitorFromWindow SystemParametersInfoW GetScrollInfo DrawIconEx DestroyIcon CallNextHookEx UnhookWindowsHookEx SetWindowsHookExW GetClassNameW GetParent SetClassLongW SetWindowLongW GetWindowLongW PtInRect OffsetRect CopyRect FrameRect FillRect DrawFocusRect ScreenToClient GetClientRect GetForegroundWindow SetMenuItemInfoW SetMenuInfo GetMenuInfo ModifyMenuW InsertMenuW CheckMenuItem GetMenuStringW SetMenu GetMenu TranslateAcceleratorW CharNextW GetWindowTextLengthW GetWindowTextW ShowScrollBar SetScrollPos RedrawWindow ValidateRect InvalidateRect EndPaint BeginPaint ReleaseDC GetWindowDC GetDC UpdateWindow DrawTextW TrackPopupMenuEx GetSystemMetrics IsWindowEnabled KillTimer SetTimer ReleaseCapture SetCapture IsZoomed IsWindowVisible SetWindowPos MoveWindow ShowWindow IsChild CreateWindowExW CallWindowProcW IsMenu GetIconInfo GetWindowThreadProcessId DefWindowProcW PostMessageW GetSysColor EmptyClipboard SetClipboardData CloseClipboard OpenClipboard LoadCursorW InflateRect GetSysColorBrush SetCursor SetWindowTextW GetDlgItem EndDialog DialogBoxIndirectParamW SendMessageW SetScrollInfo |
GDI32.dll |
RestoreDC
SetBrushOrgEx SetPixel PatBlt SaveDC SetROP2 GetPixel ExcludeClipRect CreatePatternBrush CreateBitmap SelectClipRgn RectInRegion GetBkMode CreateRectRgnIndirect SetBkMode CreateRectRgn GdiFlush GetCurrentObject CreateFontW GetObjectW GetBitmapBits GetBkColor CreateDIBSection SetViewportOrgEx Polyline Polygon ExtTextOutW TextOutW MoveToEx GetTextMetricsW SetMapMode GetDeviceCaps SetTextColor SetBkColor SelectObject Rectangle LineTo GetTextExtentPoint32W GetStockObject DeleteDC CreatePen CreateFontIndirectW CreateCompatibleDC CreateCompatibleBitmap BitBlt DeleteObject CreateSolidBrush EndPage StartPage EndDoc StartDocW SetTextAlign |
COMDLG32.dll |
ChooseColorW
GetSaveFileNameW GetOpenFileNameW ChooseFontW PrintDlgW FindTextW |
ADVAPI32.dll |
RegQueryValueExW
RegOpenKeyExA RegQueryValueExA ConvertStringSidToSidW ConvertSidToStringSidW RegSetValueW RegEnumKeyW LookupAccountSidW MapGenericMask GetTokenInformation GetLengthSid FreeSid EqualSid AllocateAndInitializeSid RegQueryInfoKeyW RegEnumValueW RegEnumKeyExW RegCreateKeyExW RegDeleteValueW RegDeleteKeyW LookupPrivilegeValueW AdjustTokenPrivileges OpenProcessToken RegSetValueExW RegCreateKeyW RegOpenKeyExW RegOpenKeyW RegCloseKey |
SHELL32.dll |
SHGetSpecialFolderLocation
ShellExecuteW SHGetPathFromIDListW CommandLineToArgvW SHChangeNotify SHBrowseForFolderW ExtractIconExW SHGetMalloc DragQueryFileW ShellExecuteExW SHGetFileInfoW |
ole32.dll |
CoTaskMemFree
RegisterDragDrop ReleaseStgMedium CoTaskMemRealloc OleUninitialize CreateBindCtx OleInitialize CoTaskMemAlloc CoCreateInstance CoSetProxyBlanket CoInitializeEx |
OLEAUT32.dll |
SysFreeString
SysStringLen SafeArrayDestroy SafeArrayGetUBound SafeArrayGetLBound SafeArrayAccessData SafeArrayUnaccessData SysAllocString VariantInit VariantClear VariantChangeType SysAllocStringByteLen VarUI4FromStr VariantTimeToSystemTime SysAllocStringLen SafeArrayGetElement |
SHLWAPI.dll |
SHAutoComplete
|
UxTheme.dll |
IsAppThemed
SetWindowTheme IsThemeActive |
dwmapi.dll |
DwmSetWindowAttribute
DwmDefWindowProc |
ntdll.dll |
RtlGetVersion
|